Course Glossary
Author & Course Lead — Badr Tajini · ESILV · 2026–2027
| Term | Operational meaning in this course |
|---|---|
| Artifact | A file or image produced by a build and identified so it can be verified later. |
| Attestation | Signed or verifiable metadata asserting how an artifact was produced. |
| Build context | Files made available to a Docker build; reduce it with .dockerignore. |
| Capability | A discrete Linux kernel privilege that can be dropped independently of UID 0. |
| CI | Automated integration checks triggered by repository events. |
| CD | Controlled delivery of a releasable artifact; automatic production deployment is not required here. |
| Claim | A falsifiable statement about configuration or runtime behavior. |
| Compose | A declarative model for a related set of containers on a Docker host. |
| Container | A running or stopped process environment created from an image plus runtime configuration. |
| Control plane | The component that decides desired state; Docker Engine has a daemon API, while Kubernetes adds a distributed reconciliation control plane. |
| Definition | Versioned source such as a Dockerfile, Compose file, workflow or runbook. |
| Digest | Content-addressed identifier; unlike a tag, it changes when content changes. |
| Docker daemon | Privileged service managing Docker objects; access to its socket is effectively host-level control. |
| Dockerfile | Ordered build definition for an image. |
| Entrypoint | Executable a container starts as its primary process. |
| Evidence | Captured output tied to a test and a claim. |
| Exit status | Integer returned by a process; zero conventionally means success. |
| Git SHA | Identifier of a Git commit used here to trace source to an image tag. |
| GHCR | GitHub Container Registry. |
| Health check | Repeated probe reporting process/service health; it is not automatically readiness. |
| Host port | Socket on the Docker host mapped to a container port. |
| Image | Immutable filesystem/configuration template used to create containers. |
| Image ID | Local Docker identifier; not a portable release coordinate. |
| Immutable release | Release selected by content digest and protected from silent tag movement. |
| Layer | Content-addressed filesystem change reused across image builds. |
| Least privilege | Grant only the identities, capabilities, mounts and network access required by the contract. |
| Loopback | Address reachable only from the same network namespace, normally 127.0.0.1. |
| Multi-stage build | Dockerfile with multiple build stages so tools and source need not enter the runtime image. |
| Negative test | Test proving a prohibited behavior is denied for the intended reason. |
| Network namespace | Kernel isolation of interfaces, routes and sockets for a process group. |
| OCI | Open Container Initiative specifications for images, runtimes and distribution. |
| PID 1 | First process in a container namespace, responsible for receiving signals and reaping children. |
| Positive test | Test proving an explicitly allowed behavior succeeds. |
| Promotion | Deliberate move of an already-built artifact into a later environment. |
| Readiness | Ability to serve the complete dependency-backed request contract now. |
| Registry | Service that stores and distributes images by repository, tag and digest. |
| Replayability | Another engineer can rerun the documented test from declared preconditions. |
| Residual risk | Known risk remaining after controls, with an owner or explicit acceptance. |
| Rollback | Restore the previously recorded known-good release. |
| Rootless Docker | Docker daemon and containers operated without a root-owned daemon; an extension topic. |
| Runtime contract | Machine-readable declaration of ports, probes, configuration, persistence, resources, identity, shutdown and recovery. |
| SBOM | Software bill of materials listing components in an artifact. |
| Secret | Sensitive value requiring controlled injection, redaction and rotation. |
| Service discovery | Resolution of a stable service name to a reachable endpoint inside a network. |
| Signal | Kernel notification such as SIGTERM used for graceful shutdown. |
| Smoke test | Cheap test proving the minimum runnable contract. |
| Tag | Mutable human-readable image label; useful for discovery but insufficient as deployment identity. |
| Test card | Structured link between claim, definition, test, result, evidence and recovery. |
| Threat model | Explicit account of assets, trust boundaries, attacker abilities, abuse cases and mitigations. |
| Volume | Docker-managed persistent data location independent of a container lifecycle. |
| Vulnerability triage | Decision process that validates scanner findings, exposure, remediation and accepted residual risk. |